Getting Data In

splunk behind a revproxy

RobertFidler
New Member

Hello,

My setup:

remote server:
-I have a universal forwarder setup on a GlassFish server.

splunk server (Splunk 4.2):
-I have free splunk setup to only communicate on 127.0.0.1
-I have iPlanet WS7 installed and acting as a reverse proxy
--I have two virtual servers setup, one to handle the web interface and one to handle the forwarder communication

Now my issue is that the request getting sent to splunk via the forwarder are returning with a 400 status code and the message "--splunk-cooked-mode-v2--".

Has anyone used a similar setup? and if so how did you handle your forwarder communication? I was thinking I could setup a light forwarder splunk instance on my server that proxies the data between my external ip and my internal ip, but I would like a cleaner solution (i.e. using my iPlanet WebServer).

When proxying forwarder communication via a reverse proxy are there any settings I should be aware of and might be missing? Should I be rewriting some of the headers, change forwarder paramaters ...etc ?

Thanks
Rob

0 Karma

MaximusBCSplunk
Engager

as of May/2012 it's was not supported, nor tested by Splunk I've spent lots of time trying to make it working but no success... Then I got the above answer from support...

Did you manage to get Splunk forwarder sending data to indexer through Apache reverse proxy? I need this feature too

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...